eNSP-无线技术原理
一、实验拓扑:
二、配置思路:
1、配置交换机接口允许业务vlan 20和管理vlan 10通过。
2、配置AC,通过CAPWAP协议下放配置和管理数据,实现AC对AP的控制。
1)创建并管理vlan(基于接口开启DHCP服务)
2)创建AP组
3)配置管理域模板
4)建立CAPWAP隧道
5)配置安全模板
6)AP认证
7)配置SSID模板
8)配置VAP模板
9)AP添加射频
三、实验配置:
1)SW1配置:
[Huawei]interface GigabitEthernet 0/0/1
[Huawei-GigabitEthernet0/0/1]port link-type trunk
[Huawei-GigabitEthernet0/0/1]port trunk pvid vlan 10//抑制管理vlan
[Huawei-GigabitEthernet0/0/1]port trunk allow-pass vlan 10 20
[Huawei]interface GigabitEthernet 0/0/2
[Huawei-GigabitEthernet0/0/1]port link-type trunk
[Huawei-GigabitEthernet0/0/1]port trunk allow-pass vlan 10 20
2)AC配置:
[AC6005]vlan batch 10 20//创建管理vlan、业务vlan
[AC6005]interface GigabitEthernet 0/0/1
[AC6005-GigabitEthernet0/0/1]port trunk allow-pass vlan 10 20
[AC6005]interface Vlanif 10
[AC6005-Vlanif10]ip address 10.0.10.1 24
[AC6005-Vlanif10]dhcp select interface //基于接口开启DHCP功能
[AC6005]interface Vlanif 20
[AC6005-Vlanif20]ip address 10.0.20.1 24
[AC6005-Vlanif20]dhcp select interface
[AC6005]wlan
[AC6005-wlan-view]ap-group name we//创建AP组
[AC6005]wlan
[AC6005-wlan-view]regulatory-domain-profile area//创建管理域模板
[AC6005-wlan-regulate-domain-area]country-code CN //配置AC国家码
[AC6005-wlan-regulate-domain-area]q
[AC6005-wlan-view]ap-group name AP //域管理绑定至AP组
[AC6005-wlan-ap-group-AP]regulatory-domain-profile area //绑定域管理模板
[AC6005]capwap source interface Vlanif 10//建立CAPWAP隧道
[AC6005]wlan
[AC6005-wlan-view]ap auth-mode mac-auth //使用MAC地址认证
[AC6005-wlan-view]ap-mac 00e0-fc54-7890 ap-id 1 //配置认证
[AC6005-wlan-ap-0]ap-group we //添加至AP组
[AC6005-wlan-view]security-profile name 1//配置安全模板
[AC6005-wlan-view]ssid-profile name 1 //配置SSID模板1
[AC6005-wlan-ssid-prof-1]ssid 1 //SSID配置1
[AC6005-wlan-ssid-prof-1]q
[AC6005-wlan-view]ssid-profile name 2
[AC6005-wlan-ssid-prof-2]ssid 2
[AC6005]wlan
[AC6005-wlan-view]vap-profile name 1 //配置VAP模板1
[AC6005-wlan-vap-prof-1]forward-mode direct-forward //配置直接转发
[AC6005-wlan-vap-prof-1]service-vlan vlan-id 20 //指定业务VLAN
[AC6005-wlan-vap-prof-1]security-profile 1 //调用安全模板1
[AC6005-wlan-vap-prof-1]ssid-profile 1 //调用SSID模板
[AC6005-wlan-vap-prof-1]q
[AC6005-wlan-view]vap-profile name 2
[AC6005-wlan-vap-prof-2]forward-mode direct-forward
[AC6005-wlan-vap-prof-2]service-vlan vlan-id 20
[AC6005-wlan-vap-prof-2]security-profile 1
[AC6005-wlan-vap-prof-2]ssid-profile 2
[AC6005-wlan-view]ap-group name we
[AC6005-wlan-ap-group-we]vap-profile 1 wlan 1 radio 0//AP添加射频
[AC6005-wlan-ap-group-we]vap-profile 2 wlan 2 radio 1